Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40192

Опубликовано: 15 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия от 10.3.0 (включая) до 12.2.0 (исключая)

EPSS

Процентиль: 48%
0.00671
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-409

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
redhat
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
debian
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...

suse-cvrf
3 месяца назад

Security update for python-Pillow

CVSS3: 7.5
github
4 месяца назад

FITS GZIP decompression bomb in Pillow

EPSS

Процентиль: 48%
0.00671
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-409